CVE-2026-51747
Unauthenticated MQTT access-control flaw in TOTOLINK T6 mesh router keepAlive
CVE-2026-51747 is an incorrect access control flaw (CWE-284) in the keepAlive function of the MQTT-based cs_broker component in TOTOLINK T6 mesh routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the MQTT service can send a crafted MQTT message that causes the device to emit indirect mesh heartbeat information toward the master node, effectively letting an unauthenticated party inject or disclose mesh status traffic. The CVSS 3.1 score of 9.8 rates potential confidentiality, integrity, and availability impact as high, although no public exploit demonstrates the full scope of compromise. Any deployment of the TOTOLINK T6 on the affected firmware is affected, especially networks where the MQTT broker is reachable beyond the local LAN. Exploitation has not been observed: the flaw is not in CISA KEV, no public PoC is known, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.
What to do: Inventory TOTOLINK T6 units and identify any running firmware 4.1.5cu.748_B20211015, then upgrade to a patched firmware when TOTOLINK publishes one, as no fixed version is named in the current data. As an interim mitigation, restrict access to the cs_broker MQTT service by keeping MQTT ports off the WAN interface and limiting them to the trusted LAN, and monitor for unexpected MQTT/heartbeat traffic toward the master node. Track TOTOLINK advisories for a firmware release addressing this issue.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.